aboutsummaryrefslogtreecommitdiffstats
path: root/sys/fuchsia/init.go
diff options
context:
space:
mode:
authorDmitry Vyukov <dvyukov@google.com>2018-02-19 19:35:04 +0100
committerDmitry Vyukov <dvyukov@google.com>2018-02-19 21:48:20 +0100
commit75a7c5e2d1f09a4a58e7e1f1f4ef0b0f55a33413 (patch)
treed44c2457c44b53192005f0b89cd6633a2a2b0ff9 /sys/fuchsia/init.go
parent90fd6503136121e9494761a460898e83bc0b6b3e (diff)
prog: rework address allocation
1. mmap all memory always, without explicit mmap calls in the program. This makes lots of things much easier and removes lots of code. Makes mmap not a special syscall and allows to fuzz without mmap enabled. 2. Change address assignment algorithm. Current algorithm allocates unmapped addresses too frequently and allows collisions between arguments of a single syscall. The new algorithm analyzes actual allocations in the program and places new arguments at unused locations.
Diffstat (limited to 'sys/fuchsia/init.go')
-rw-r--r--sys/fuchsia/init.go25
1 files changed, 3 insertions, 22 deletions
diff --git a/sys/fuchsia/init.go b/sys/fuchsia/init.go
index 12ee37daf..f3299e178 100644
--- a/sys/fuchsia/init.go
+++ b/sys/fuchsia/init.go
@@ -12,40 +12,21 @@ func initTarget(target *prog.Target) {
mmapSyscall: target.SyscallMap["syz_mmap"],
}
- target.PageSize = pageSize
- target.DataOffset = dataOffset
- target.MmapSyscall = arch.mmapSyscall
target.MakeMmap = arch.makeMmap
- target.AnalyzeMmap = arch.analyzeMmap
}
-const (
- pageSize = 4 << 10
- dataOffset = 512 << 20
-)
-
type arch struct {
mmapSyscall *prog.Syscall
}
-func (arch *arch) makeMmap(start, npages uint64) *prog.Call {
+func (arch *arch) makeMmap(addr, size uint64) *prog.Call {
meta := arch.mmapSyscall
return &prog.Call{
Meta: meta,
Args: []prog.Arg{
- prog.MakePointerArg(meta.Args[0], start, 0, npages, nil),
- prog.MakeConstArg(meta.Args[1], npages*pageSize),
+ prog.MakeVmaPointerArg(meta.Args[0], addr, size),
+ prog.MakeConstArg(meta.Args[1], size),
},
Ret: prog.MakeReturnArg(meta.Ret),
}
}
-
-func (arch *arch) analyzeMmap(c *prog.Call) (start, npages uint64, mapped bool) {
- switch c.Meta.Name {
- case "syz_mmap":
- npages = c.Args[1].(*prog.ConstArg).Val / pageSize
- start = c.Args[0].(*prog.PointerArg).PageIndex
- mapped = true
- }
- return
-}